Create a report from a sparkline chart
In this example, you create a report that shows the trends in the number of purchases made over time. This example uses sparkline charts. Sparklines are inline charts that appear in the search results table and are designed to display time-based trends associated with the primary key of each row.
For searches that use the
chart commands, you can add sparkline charts to the results table.
This example uses the
productName field from the Enabling field lookups section of this tutorial.
If you do not configure the field lookups, the searches in this section will not produce the correct results.
- Start a new search.
- Set the time range to All time.
- Run the following search.
sourcetype=access_* status=200 action=purchase| chart sparkline(count) AS "Purchases Trend" count AS Total BY categoryId | rename categoryId AS Category
This search uses the
chartcommand to count the number of purchases by using
action="purchase". The search specifies the purchases made for each product by using
categoryId. The difference is that the count of purchases is now an argument of the
When you rename a column using the AS keyword, names that are more than one word need to be in quotation marks. In this search quotation marks are around the name Purchases Trend but not around the name Category.
- Click Save As and select Report.
- In the Save Report As dialog box, for Title type
- For Description, type
Count of purchases with trends.
- Click Save.
- In the confirmation dialog box, click View. Your report should look like this.
This completes Part 6 of the Search Tutorial.
Up to now, you have saved searches as Reports. Continue to Part 7: Creating dashboards, where you learn how to save searches and reports as dashboard panels.
Create a report from a custom chart
This documentation applies to the following versions of Splunk® Enterprise: 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9